June Analytics
ENFR

Privacy Policy

Last updated August 13, 2026

June Analytics builds financial reporting and forecasting software for Canadian accounting firms and the businesses they serve. Handling other people's financial records is the whole job, so this page says plainly what we collect, where it lives, and what we will never do with it.

What we collect

Account information you give us: your name, email address, the name of your firm, and the role you hold in it. If you set up two-factor authentication we store the secret needed to verify your codes, not your codes.

Financial data from QuickBooks, once you connect a company. Specifically: Profit and Loss, Balance Sheet and Cash Flow reports, accounts receivable and accounts payable aging, and a general ledger transaction list. We store the output of those reports so the product does not have to re-query Intuit on every page load.

Ordinary technical records that come with running a web application, such as request logs and error reports.

What we never collect

We never see or store your QuickBooks password. The connection is made through Intuit's OAuth flow, which hands us a token and nothing else.

We do not collect payment card numbers, bank account numbers, or government identification through the product.

We do not buy personal information from data brokers, and we do not enrich your account with information bought from anyone else.

How we use it

To operate the product: to show you your reports, calculate metrics and forecasts, and let the people at your firm work on the same client file.

To contact you about your account, including onboarding reminders and service notices.

To find and fix problems. Engineers investigating a fault may need to look at the data involved in it.

What we do not do with it

We do not sell your data, and we do not rent or share it for anyone else's advertising.

We do not use your clients' financial data to train machine learning models for other customers.

We do not modify anything in your QuickBooks company. June reads from QuickBooks and never writes to it.

Where your data is stored

The application runs on Vercel in the US East region, and the database is Postgres hosted by Supabase in the US West region (Oregon). Both are in the United States. If your firm needs Canadian data residency, contact us before connecting a client so we can tell you honestly whether we can meet that requirement today.

QuickBooks access tokens are encrypted with AES-256-GCM before they reach the database, using a key held outside it. Tokens are never written to logs.

Who else touches it

We keep the list of third parties short, and each one is here because the product cannot run without it:

  • Intuit, the source of the QuickBooks data you ask us to read.
  • Supabase, which hosts the database and handles authentication.
  • Vercel, which hosts and serves the application.
  • Resend, which delivers transactional email such as invitations and reminders.
  • Anthropic, which powers the optional AI forecasting features. See below.

None of these is permitted to use your data for their own purposes.

AI features and your financial data

June includes optional AI features that draft a forecast or explain a variance from a client's financial history. Where one of those features is used, the figures it works from are sent to Anthropic to produce the answer, and are not used to train anyone's models.

These features are off unless a firm asks for them. They are disabled by default, switched on per firm, and are not enabled on any account today.

If your firm would rather no client data ever reached a model, say so and we will keep them off. Nothing else in June depends on them.

Who at your firm can see what

Client data belongs to the firm, not to whoever connected it. Everyone at your firm with the right role can see the clients your firm has connected, and a report synced by one person is visible to the rest of the team without syncing again.

Separation between firms is enforced in the database itself, not only in the application. One firm cannot read another firm's data even if a bug in our code tried to allow it.

Inside a firm, roles decide who can do what. Removing or restoring a client requires an admin or a manager.

How long we keep it

Disconnecting a client is reversible. The record is kept for 90 days so that work built on it, such as forecasts and saved metrics, is not stranded, and so an accidental removal is a one-click fix.

Nothing is deleted automatically after that window. Records past it are surfaced internally and removed deliberately.

If you close your account and want everything erased, write to us and we will delete it.

Your rights

Canadian privacy law gives you the right to ask what personal information we hold about you, to have it corrected if it is wrong, and to have it deleted. Write to us and we will answer.

If you are unhappy with how we have handled a request, you can raise it with the Office of the Privacy Commissioner of Canada.

Security incidents

If your data is involved in a breach we will tell you, and the relevant regulator, as required by law. We will tell you what happened rather than the smallest thing we can get away with saying.

Changes

If we change this policy in a way that materially affects you, we will let you know rather than quietly updating the date at the top.

Contact

Questions about this policy, or a request about your data, can go to our contact page. We answer privacy questions personally.